Domain controller metadata cleanup removes every trace of a DC that no longer exists: its NTDS Settings object, computer account, replication connections, DFSR membership for SYSVOL and the DNS records that still send clients to it. You need it whenever a DC dies, is rebuilt, or is forcibly demoted. This guide first covers the clean path, a graceful demotion, and then the forced removal, FSMO seizure, metadata cleanup and DNS cleanup for a DC that cannot be demoted normally.
Short answer: If the DC still works and can reach another DC, run Uninstall-ADDSDomainController (or Server Manager’s Demote this domain controller) and no cleanup is needed. If the DC is dead, seize its FSMO roles with Move-ADDirectoryServerOperationMasterRole -Force, delete its computer object in Active Directory Users and Computers with the “permanently offline” checkbox ticked, remove its leftover DNS records, and confirm with repadmin /replsummary and dcdiag.
Table of Contents
Which method to use
| Situation | Method | Metadata cleanup needed? |
|---|---|---|
| DC is healthy and can replicate with a partner | Graceful demotion (Server Manager or Uninstall-ADDSDomainController) | No, demotion removes its objects |
| DC is the last one in the domain | Graceful demotion with -LastDomainControllerInDomain | No, the domain is removed |
| DC boots but cannot reach any other DC | Forced removal (-ForceRemoval) | Yes, on the remaining DCs |
| DC is dead, deleted or will never return | No demotion possible; seize roles and clean up | Yes |
| DC restored from an old snapshot, USN rollback | Forced removal, cleanup, then re-promote | Yes |
Forced removal loses every change that existed only on that DC and leaves orphaned metadata behind. Microsoft notes that orphaned metadata is behind a significant share of its AD DS support cases, so treat domain controller metadata cleanup as mandatory after any forced removal.
What metadata cleanup removes
Every DC is represented in several places in Active Directory. A graceful demotion removes them all; a dead DC leaves them behind. Domain controller metadata cleanup deletes:
- The NTDS Settings object under the server object in
CN=Sites,CN=Configuration, which tells the Knowledge Consistency Checker (KCC) that the DC exists and should receive replication. - The inbound and outbound connection objects other DCs created to replicate with it.
- The DC’s computer account in the Domain Controllers OU, and the FRS or DFSR member objects that made it part of SYSVOL replication.
- References that make the DC a FSMO role holder, which the cleanup offers to transfer or seize.
Until these objects are gone, the remaining DCs keep trying to replicate with the missing server. You see replication errors such as 1722 (RPC server unavailable) or 8524 (DNS lookup failure), KCC warnings in the Directory Service log, and dcdiag failures that hide real problems. Some applications, including Exchange and older backup agents, also read the list of DCs from the Configuration partition and try the dead one.
Plan the removal
Whether you demote or run domain controller metadata cleanup, answer these questions first and write the answers in the change record:
- Which roles does the DC hold? Check FSMO roles (
netdom query fsmo), global catalog, DNS, DHCP, certificate services, NPS and any file shares. - Which clients use it directly? Look at DHCP scopes, static DNS settings on servers, LDAP bind settings in applications and appliances, and time synchronisation.
- Which site will lose its only DC? Clients there will authenticate across the WAN; decide whether that is acceptable.
- Is replication healthy on the remaining DCs? Fix existing errors first, or the cleanup will be harder to verify.
Prerequisites
- Domain Admins membership for DCs in the domain; Enterprise Admins to remove the last DC of a child domain, seize the schema or domain naming master, or remove application partitions.
- The RSAT AD DS tools and the
ActiveDirectoryPowerShell module on the machine you work from. - At least one other healthy DC in the domain that is a global catalog and DNS server. Check with
Get-ADDomainController -Filter * | Select-Object Name, Site, IsGlobalCatalog, OperationMasterRoles. - A recent system state backup of a remaining DC.
- Clients and member servers that list the old DC as a DNS server must be updated first (DHCP option 006, static NIC settings, conditional forwarders, and appliances such as firewalls or printers that use LDAP).
Method 1: graceful demotion
Before you start
- Move FSMO roles off the DC. Demotion transfers them automatically, but choosing the target yourself is cleaner:
Get-ADDomainController -Identity DC01 | Select-Object OperationMasterRoles
Move-ADDirectoryServerOperationMasterRole -Identity DC02 -OperationMasterRole PDCEmulator, RIDMaster, InfrastructureMaster
In this guide DC01 is the server being removed and DC02 is the surviving DC;-Identitynames the DC that receives the roles. - If it is a global catalog, make sure another DC in the same site is one too.
- If it holds the PDC emulator, reconfigure the new PDC as the authoritative time source.
- Check replication is healthy:
repadmin /replsummaryshould show no failures.
Demote with PowerShell
Run a pre-check first, then the demotion. You are prompted for a new local Administrator password, which the server uses once it becomes a member server:
Test-ADDSDomainControllerUninstallation
Uninstall-ADDSDomainController -Credential (Get-Credential CONTOSO\admin)
The server restarts as a member server. Remove the role binaries afterwards:
Uninstall-WindowsFeature -Name AD-Domain-Services -IncludeManagementTools -Restart
Useful switches:
| Parameter | What it does |
|---|---|
-LastDomainControllerInDomain | States that this is the last DC, which removes the domain |
-RemoveApplicationPartitions | Removes application partitions (for example DNS partitions) hosted only here |
-RemoveDnsDelegation | Removes DNS delegations pointing to this server from the parent zone |
-IgnoreLastDnsServerForZone | Continues even if this is the last DNS server for an AD-integrated zone |
-DemoteOperationMasterRole | Lets a forced demotion continue when the DC still holds FSMO roles |
-ForceRemoval | Removes AD DS without contacting other DCs (Method 2) |
-NoRebootOnCompletion | Suppresses the restart; Microsoft recommends it only for testing |
Demote with Server Manager
- In Server Manager, choose Manage » Remove Roles and Features and select the server.
- Untick Active Directory Domain Services. When prompted, click Remove Features, then Demote this domain controller in the validation message.
- In the AD DS Configuration Wizard, supply credentials. Leave “Force the removal of this domain controller” unticked, unless the DC cannot contact any other DC.
- Tick Last domain controller in the domain only if that is true. Confirm the warnings about DNS and global catalog roles.
- Enter a new local Administrator password, review the summary and click Demote. After the restart, run the wizard again to remove the AD DS role itself.
Last DC in the domain
Demoting the final DC removes the domain from the forest. For a child domain, you need Enterprise Admins credentials and the parent domain’s DCs must be reachable. Remove any member computers and trusts first, and use -LastDomainControllerInDomain -RemoveApplicationPartitions. For the last DC in the forest, the forest itself disappears; take a final backup and make sure nothing depends on it, because there is no undo.
Method 2: forced removal
Use forced removal only when the DC still starts but has no way to reach another DC, for example after a site was permanently disconnected or the server was restored from an old snapshot.
Uninstall-ADDSDomainController -ForceRemoval -DemoteOperationMasterRole -Force
In Server Manager, tick “Force the removal of this domain controller”. The server becomes a workgroup or member server, but the rest of the domain still believes the DC exists. Continue with FSMO seizure (if it held roles) and domain controller metadata cleanup on a surviving DC.
Seize FSMO roles from a dead DC
If the failed DC held operations master roles, seize them onto a healthy DC before or during cleanup. Transfer is impossible because the old holder cannot respond. Seizing is permanent: the old DC must never come back online with those roles.
PowerShell
netdom query fsmo
Move-ADDirectoryServerOperationMasterRole -Identity DC02 -OperationMasterRole SchemaMaster, DomainNamingMaster, PDCEmulator, RIDMaster, InfrastructureMaster -Force
Run the command against a DC in the same domain for the PDC emulator, RID master and infrastructure master roles; the schema and domain naming master roles are forest-wide and need Enterprise Admins rights.
ntdsutil
ntdsutil
roles
connections
connect to server DC02
quit
seize schema master
seize naming master
seize rid master
seize pdc
seize infrastructure master
quit
quit
Seize only the roles the dead DC held. Seizing the RID master deliberately skips a block of RIDs to avoid duplicates, which is expected. The new holder waits for one successful inbound replication of the relevant partition before it acts on the role.
Method 3: domain controller metadata cleanup
Since Windows Server 2008, deleting a DC object with the GUI performs metadata cleanup for you, including the NTDS Settings object and the SYSVOL DFSR membership. Pick one of the three options below and run it against a surviving DC that was a replication partner of the removed one.
Option A: Active Directory Users and Computers
- Open Active Directory Users and Computers and connect to a healthy DC.
- Open the Domain Controllers OU, right-click the dead DC and choose Delete, then confirm.
- In the Deleting Domain Controller dialog, tick “This Domain Controller is permanently offline and can no longer be demoted using the Active Directory Domain Services Installation Wizard (DCPROMO)” and click Delete.
- If it was a global catalog, confirm with Yes. If it still held FSMO roles, click OK to move them to the DC shown.
If Delete is greyed out, the object is protected from accidental deletion. Enable View » Advanced Features, open the object’s Object tab and clear the protection checkbox.
Option B: Active Directory Sites and Services
- Open Active Directory Sites and Services and expand Sites » <site> » Servers » <DC name>.
- Right-click NTDS Settings, choose Delete and tick the same “permanently offline” checkbox.
- Once NTDS Settings is gone, right-click the server object itself and delete it. If other child objects remain under it (for example from another application), leave the server object in place.
Always check Sites and Services after Option A as well: the server object often stays behind in the site and should be removed as the last step of domain controller metadata cleanup.
Option C: ntdsutil
Use ntdsutil on Server Core or when the GUI refuses. The remove selected server command takes the distinguished name of the server object:
ntdsutil
metadata cleanup
connections
connect to server DC02
quit
remove selected server "CN=DC01,CN=Servers,CN=HQ,CN=Sites,CN=Configuration,DC=contoso,DC=com"
quit
quit
Confirm the Server Remove Configuration dialog. If ntdsutil reports that the object cannot be found, the metadata was already removed. Find the correct DN with Get-ADObject -SearchBase (Get-ADRootDSE).configurationNamingContext -Filter "objectClass -eq 'server' -and name -eq 'DC01'".
Clean up DNS records
Domain controller metadata cleanup does not always remove every DNS record the old DC registered. Leftover records make clients try the dead DC first, which slows logons and breaks some applications. In DNS Manager on a surviving DC, check each of these:
| Location | Record |
|---|---|
contoso.com zone | A/AAAA record for the DC name, and the same-as-parent A record holding its IP |
contoso.com zone properties » Name Servers | NS entry for the dead DC |
_msdcs.contoso.com zone | CNAME named after the DC’s DSA GUID; NS entry; gc._msdcs A record |
_msdcs.contoso.com » dc, gc, pdc, domains | SRV records (_ldap, _kerberos) pointing to the DC |
contoso.com » _sites, _tcp, _udp | SRV records for _ldap, _kerberos, _kpasswd, _gc |
| Parent zone (child domains) and reverse lookup zones | Delegation NS records and PTR records |
PowerShell makes the search easier. The example lists every record in the domain zone that points to the old DC’s name or IP address:
$zone = 'contoso.com'
Get-DnsServerResourceRecord -ZoneName $zone -ComputerName DC02 |
Where-Object { $_.RecordData.DomainName -like 'dc01.*' -or $_.RecordData.NameServer -like 'dc01.*' -or $_.RecordData.HostNameAlias -like 'dc01.*' -or $_.RecordData.IPv4Address -eq '10.0.0.10' } |
Format-Table HostName, RecordType, RecordData -AutoSize
Repeat for _msdcs.contoso.com, review the list, then remove each record with Remove-DnsServerResourceRecord or in DNS Manager. The nltest /dsderegdns:dc01.contoso.com command can also deregister the DC’s records when run on a DC.
SYSVOL and DFSR membership
SYSVOL on Windows Server 2016 and later replicates with DFSR. Deleting the DC object through the GUI or ntdsutil removes its member object in the Domain System Volume replication group. Check in ADSI Edit or with PowerShell that nothing is left:
Get-ADObject -SearchBase "CN=Topology,CN=Domain System Volume,CN=DFSR-GlobalSettings,CN=System,DC=contoso,DC=com" -Filter * |
Select-Object Name, DistinguishedName
If a member object named after the old DC remains, delete it. Also remove the old DC from any DFS Namespaces and custom DFS Replication groups it served.
Verify it works
repadmin /replsummary
repadmin /showrepl * /csv > C:\Temp\showrepl.csv
dcdiag /e /v /q
nltest /dclist:contoso.com
Get-ADDomainController -Filter * | Select-Object Name, Site, OperationMasterRoles
netdom query fsmo
repadmin /replsummarymust no longer list the old DC as a source or destination.dcdiag /e /qtests every DC in the enterprise and prints only errors; the old DC must not appear.nltest /dclistandGet-ADDomainControllershow only the remaining DCs.Resolve-DnsName -Type SRV _ldap._tcp.dc._msdcs.contoso.comreturns only live DCs.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Demotion fails: cannot contact another DC | DNS points only to itself or partner unreachable | Set DNS to a partner DC; if still unreachable, use forced removal |
| Delete is greyed out in ADUC | Protected from accidental deletion | Clear the protection flag on the Object tab (Advanced Features) |
| Replication errors 1722 or 8524 still name the old DC | Connection objects or DNS records remain | Delete stale connection objects in Sites and Services; clean DNS records |
| Seized role reverts or shows the old DC | Old DC came back online | Keep it offline permanently; wipe and reinstall before reuse |
| Clients log on slowly after removal | SRV or A records still point to the old DC | Remove records in _msdcs, _sites, _tcp and the zone root |
| “Object cannot be found” in ntdsutil | Wrong DN or already cleaned | Look up the server object DN in the Configuration partition |
Reusing the old server
A DC that was forcibly removed or had its roles seized must not rejoin the network as it is. Wipe and reinstall it, or at least complete the forced removal on it before connecting it. Then, after domain controller metadata cleanup has replicated everywhere, give it a new name (or wait for replication before reusing the old one), join the domain and promote it as a new DC.
Domain controller metadata cleanup at a glance

Official documentation: Demoting domain controllers and domains, Clean up Active Directory Domain Controller server metadata, Transfer or seize Operation Master roles in AD DS.
Related guides: Transfer FSMO Roles with PowerShell and ntdsutil: Safe Steps · dcdiag repadmin Health Check: 7 Critical Tests Explained · Install and promote a Windows Server 2025 domain controller step by step.
Frequently asked questions
Do I need metadata cleanup after a normal demotion?
No. A graceful demotion removes the DC’s NTDS Settings object, computer account role and DNS registrations itself. Domain controller metadata cleanup is required after forced removal or when a DC dies and cannot be demoted.
Should I seize FSMO roles before or after metadata cleanup?
Seize them first on a healthy DC with Move-ADDirectoryServerOperationMasterRole -Force or ntdsutil. Deleting the DC in Active Directory Users and Computers also offers to move remaining roles, but seizing deliberately lets you choose the target.
Can a DC whose roles were seized come back online?
No. Microsoft advises never returning it to the network as a DC. Reinstall the operating system or forcibly demote it offline, clean up its metadata, and only then promote it again if you need it.
Does metadata cleanup remove DNS records?
Not reliably. Check the domain zone, the _msdcs zone, the _sites, _tcp and _udp SRV records, name server entries and reverse zones for records that still point to the old DC, and delete them.
What is the ntdsutil syntax for metadata cleanup?
Run ntdsutil, metadata cleanup, connections, connect to server with a healthy DC, quit, then remove selected server followed by the distinguished name of the old DC’s server object in the Configuration partition.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Last full review
- Next review
- Sources
- learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/demoting-domain-controllers-and-domains--level-200-
learn.microsoft.com/en-us/windows-server/identity/ad-ds/deploy/ad-ds-metadata-cleanup
learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/transfer-or-seize-operation-master-roles-in-ad-ds